A couple of important things to note here:
1. We do store all passwords hashed. We do not store plaintext passwords
2. That spot in the subject line for the update is for the name of a classroom in the Schools product. When we investigated we realized this was just a case of user-error where they must have typed their password in as a classroom name when they created a class.
3. I'm not positive if we ever responded to the report... I'm trying to find the thread. If we didn't respond, that's my fault and I'm very sorry. Not a great user experience to think your password is stored in plaintext!
I'm trying to find the email thread where I first encountered this so that I can understand more thoroughly what's going on.
UPDATE: The discussion we had internally was a slack conversation, not an email. I verified that one of the user's classroom names appears to be something someone would use for a password. Once we determined there wasn't a security issue, I didn't ask for the reporter's contact info or anything like that. I'm really sorry to Arron and his wife for the poor service & bad customer experience.